CVE detail
CVE-2013-4482 — CVE-2013-4482
Published 2013-11-23 · Modified 2026-06-16 · Vendor scientificlinux · Product luci · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0038
EPSS probability
exploitation probability, 30d
31.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current working directory or (2) its parent directories.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References